Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Gentoo: GLSA-200904-08 Normal: OpenSSL Denial Of Service

gentoo
Calendar Grey April 7, 2009
Scroller Gentoo
A Denial of Service vulnerability in OpenSSL can be triggered during the process of displaying the details of certificates. Please upgrade to the latest version to mitigate this issue.
An error in OpenSSL might allow for a Denial of Service when printing certificate details.

Summary

Gentoo Linux Security Advisory GLSA 200904-08 https://security.gentoo.org/ Severity: Normal Title: OpenSSL: Denial of Service Date: April 07, 2009 Bugs: #263751 ID: 200904-08

Synopsis ======= An error in OpenSSL might allow for a Denial of Service when printing certificate details.
Background ========= OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) as well as a general purpose cryptography library.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/openssl < 0.9.8k >= 0.9.8k
========== The ASN1_STRING_print_ex() function does not properly check the provided length of a BMPStr...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround